CVE-2015-9371 (manual_purchases)

Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

View Full Alert